1. Introduction
This Privacy Policy explains how Agrya FinLabs Private Limited (“Effortless,” “we,” “us,” or “our”) collects, uses, shares, and protects information when you use our website (www.goeffortless.ai), our Cloud-based finance and business operations platform (“Effortless”), our field workforce management application (“EffortlessGeo”), and any related services, mobile applications, and tools (collectively, the “Services”).
This policy applies to all users of our Services, including Customers, Administrators, End Users, and website visitors.
By accessing or using our Services, you acknowledge that you have read and understood this Privacy Policy. If you are an End User whose employer has enabled the Services for you, your employer's privacy practices also apply to your data.
2. Definitions
- Customer(s): Businesses, firms, or organizations that subscribe to and use the Services.
- Administrator(s): Individuals appointed by Customers to manage the use of Services, configure settings, and oversee user accounts.
- End User(s): Employees, staff, or individuals of Customers who use the Services as part of their work.
- Personal Information: Information that identifies or can be used to identify an individual, such as name, email address, phone number, device identifiers, and location data.
- Business Data: Data provided by Customers and Administrators for the purpose of using the Services, including financial records, invoices, transaction data, and employee information.
3. Information We Collect
3.1 Account Information
When you create or update an Effortless account, we collect Personal Information such as:
- Name, email address, and phone number
- Business name, address, and registration details (e.g., GSTIN, PAN)
- Billing and payment information
- Role and designation within the organization
- Profile photo (if provided)
3.2 Business and Financial Data
When you use the Effortless platform, we process Business Data that you or your Administrator provides, including:
- Invoices, bills, purchase orders, sales orders, and credit/debit notes
- Ledger entries, journal vouchers, and other accounting records
- Customer and vendor master data (names, addresses, GSTINs, bank details)
- Inventory and stock data
- Bank statements and transaction records uploaded for reconciliation
- Tax filings and compliance-related data (GST returns, TDS records)
- Any documents, files, or attachments uploaded to the platform
3.3 Location Information (EffortlessGeo)
When your employer enables EffortlessGeo for your account, we collect the following location-related data:
- GPS Coordinates: Real-time latitude and longitude of your device when you punch in/out, log a visit, or when location tracking is active.
- Background Location Data: When enabled by your Administrator, EffortlessGeo may collect your device's location in the background (i.e., even when the app is not actively in use) during the active tracking period configured by your employer. Background tracking requires a daily check-in and does not operate indefinitely without user action.
- Geofence Events: Entry and exit events when you enter or leave a predefined geographic boundary such as office premises, client sites, or warehouses.
- Location Timestamps: The date and time associated with each location data point.
- Location Accuracy and Source: Metadata about the precision of the location fix and whether it was derived from GPS, Wi-Fi, cell towers, or other sources.
- Visit Photos: Photographs captured through the app during site visits, which may contain embedded location metadata (EXIF data).
3.4 Device Information
We collect information about devices used to access the Services, including:
- Device model, manufacturer, and operating system version
- Unique device identifiers
- Browser type and version (for web access)
- Battery level at the time of location capture (EffortlessGeo)
- Network type and connectivity status (Wi-Fi, mobile data)
- App version and crash/error logs
- Language and timezone settings
3.5 Usage Information
We automatically collect information about how you interact with the Services:
- Log Data: IP address, pages/screens visited, features used, actions taken, date and time of access, and referring URLs.
- Attendance and Visit Data (EffortlessGeo): Punch-in/punch-out timestamps and locations, visit logs (client/site visited, check-in/check-out times, location), and distance travelled.
- Feature Usage: Which modules, reports, and tools you access and how frequently.
3.6 Google Workspace Data
When you connect your Google account to Effortless, we may access certain Google user data depending on the permissions you grant, such as:
- Email metadata
- Contacts
- Calendar events
We only access the minimum information necessary to provide our Services. This access is compliant with Google's API Services User Data Policy.
3.7 Cookies and Similar Technologies
Our website and Services use cookies and similar tracking technologies to collect information about your browsing activity, preferences, and device. This may include cookies from third-party analytics and service providers. You can manage cookie preferences through your browser settings.
3.8 Information from Third Parties
We may receive information about you from:
- Your employer or Administrator (e.g., employee details, organizational structure)
- Third-party integrations connected to your account (e.g., Tally ERP, banking APIs)
- Payment processors
- Publicly available business registries (e.g., GST portal for GSTIN validation)
4. How We Collect Information
We collect and receive information in the following ways:
- Directly from You: When you create an account, fill in forms, upload data, configure settings, or communicate with us.
- From Your Employer/Administrator: When your organization provides employee data to set up and manage Services.
- Automatically from Your Device: Log data and usage analytics when you access our website or Services; device information and identifiers when you install or use our mobile apps; cookies and similar technologies when you browse our website.
- Foreground Location (EffortlessGeo): When you actively use the app to punch in/out, log a visit, or interact with map features.
- Background Location (EffortlessGeo): When your Administrator enables continuous location tracking, the app accesses your device's location in the background during the configured active period. This requires a daily check-in and explicit device-level permission from you.
- Geofence Monitoring (EffortlessGeo): Your device sends location updates when you cross the boundary of a geofenced area configured by your Administrator.
- IP-Based Location: We may use your IP address to approximate your general location for security and fraud detection purposes.
- Third-Party Services and Integrations: When you connect external services (Google Workspace, Tally, banking APIs) to your Effortless account.
- Communications: When you contact us for support, participate in surveys, or interact with our social media accounts.
5. How We Use Information
5.1 Effortless Platform
We use the information collected to:
- Provide, maintain, update, and improve the Services
- Process accounting transactions, generate invoices, file GST returns, and manage financial records
- Sync data with connected integrations (e.g., Tally ERP)
- Facilitate bank reconciliation and payment processing
- Generate reports and business analytics for Customers
- Send service-related communications, alerts, and notifications
- Provide technical support and respond to your queries
- Monitor usage patterns to improve product features and user experience
- Ensure security, prevent fraud, and detect unauthorized access
- Comply with legal and regulatory obligations (e.g., GST, TDS, Income Tax)
- Administer billing, subscriptions, and account management
5.2 EffortlessGeo
We use location and related data to:
- Attendance Verification: Verify that attendance punches are made from authorized or expected locations.
- Visit Tracking: Confirm that field staff have visited assigned client sites and log visit durations and photo evidence.
- Live Tracking: Enable Administrators to view real-time location of field staff during active tracking periods for coordination and safety purposes.
- Route and Distance Tracking: Calculate distance travelled and display movement history for reimbursement, reporting, and operational planning.
- Geofence Alerts: Notify Administrators when employees enter or leave designated areas.
- Reports and Analytics: Generate location-based workforce management reports, including movement summaries, visit reports, and attendance analytics.
- Safety and Compliance: Support employee safety monitoring and regulatory compliance requirements of the employer.
5.3 Google Workspace Data
We use Google Workspace data solely to deliver the Services for which you have granted explicit consent, such as automating compliance tasks, managing scheduling, and organizing financial documents. We do not use Google Workspace data for advertising, marketing, or to develop AI/ML models.
6. Consent and Control
6.1 Employer as Data Controller
For End Users, your employer (the Customer) determines which Services and features are enabled for your account and what data is collected. Effortless acts as a data processor on behalf of your employer. Questions about your employer's data practices should be directed to your organization's Administrator.
6.2 Device-Level Permissions (EffortlessGeo)
- Location access requires explicit permission from you via your device's operating system (Android or iOS).
- You may modify or revoke location permissions at any time through your device settings.
- Background location access requires separate, explicit consent and can be revoked independently from foreground access.
- Camera access (for visit photos) requires separate device-level permission.
- Revoking permissions may limit certain features from functioning correctly.
6.3 Background Location Tracking (EffortlessGeo)
- Background location tracking operates only during the active tracking period configured by your Administrator.
- A daily check-in is required for background tracking to remain active. Tracking does not operate indefinitely without user action.
- You will be clearly informed about background location collection through the app and your device's permission prompts before it begins.
6.4 Transparency
- End Users can view their own location history, punch locations, visit logs, and movement data within the EffortlessGeo app.
- Customers and Administrators can access, export, and manage Business Data through the Effortless platform.
6.5 Communication Preferences
Service-related communications (security alerts, billing notices, critical updates) are part of the Services and cannot be opted out of. Marketing and promotional communications can be opted out of at any time using the unsubscribe link in such emails or by contacting us.
7. Data Sharing and Disclosure
We do not sell, rent, or trade your Personal Information or location data to any third party for advertising or marketing purposes. We may share information in the following circumstances:
7.1 With Your Employer/Administrator
If you are an End User, your data (including location data from EffortlessGeo) is accessible to authorized Administrators within your organization for workforce and business management purposes.
7.2 Service Providers
We engage trusted third-party service providers to support our business operations. These include:
- Cloud hosting and infrastructure providers
- Map and geolocation service providers (e.g., Google Maps APIs)
- Payment processors
- Email delivery and communication services
- Analytics and monitoring tools
- Customer support tools
These providers are contractually bound to use your data only for the purposes of providing services to us and to comply with applicable data protection requirements.
7.3 Third-Party Integrations
When you or your Administrator connects third-party services (e.g., Tally ERP, banking APIs, Google Workspace), data may be shared with those services as necessary for the integration to function. Please review the privacy policies of those third-party services.
7.4 Legal Compliance
We may disclose information if required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of Effortless, our users, or others.
7.5 Business Transfers
In the event of a merger, acquisition, reorganization, or sale of assets, user data may be transferred to the acquiring entity under strict confidentiality agreements. Users will be notified of any such transfer.
8. Data Security
We implement industry-standard security measures to protect your data, including:
- Encryption: All data in transit is encrypted using TLS. Data at rest is encrypted using AES-256 or equivalent standards.
- Access Controls: Access to user data is restricted to authorized personnel only, with multi-factor authentication and role-based access controls.
- Infrastructure Security: Our Services are hosted on secure, certified cloud infrastructure with regular security assessments.
- Monitoring and Auditing: We continuously monitor our systems for vulnerabilities and conduct periodic security audits.
- Incident Response: We maintain a security incident response process. In the event of a data breach, affected users and Customers will be notified as required by applicable law.
While we take commercially reasonable measures to protect your data, no method of electronic transmission or storage is completely secure. We cannot guarantee absolute security.
9. Data Retention and Deletion
9.1 Retention
- Business Data and Account Data: Retained for as long as the Customer's account is active and as required by the Customer's subscription and applicable laws (e.g., tax and financial record-keeping requirements under Indian law).
- Location Data (EffortlessGeo): Retained for as long as the Customer's account is active and in accordance with the Customer's data retention policies.
- Usage Logs and Analytics: Retained for a reasonable period to support product improvement, security monitoring, and troubleshooting.
- Google Workspace Data: Retained only for as long as necessary to provide the Services you have consented to.
9.2 Deletion
- Users may request deletion of their data by contacting their Administrator or by writing to us at security@goeffortless.ai.
- Upon termination of a Customer's account or upon a valid deletion request, associated data will be securely deleted within 90 days, unless retention is required by applicable law or regulation.
- Aggregated, anonymized data that cannot be used to identify individual users may be retained for product analytics and improvement.
10. Google Workspace API Data
10.1 Limited Use
Effortless does not retain, store, or use any data obtained through Google Workspace APIs, including Gmail, for developing, improving, or training generalized Artificial Intelligence (AI) and/or Machine Learning (ML) models. Our use of this data is strictly limited to providing the requested Services directly to the user.
10.2 Scope of Access
Effortless may access certain Google user data when you connect your Google account, such as email metadata, contacts, and calendar events, depending on the permissions you grant. We only access the minimum required information necessary to provide our Services. This access is compliant with Google's API Services User Data Policy.
10.3 No Third-Party Sharing for Non-Service Purposes
Google user data is not shared with third parties except:
- Service Providers who perform specific functions for us and are bound by data protection agreements.
- Legal Compliance requirements as described in Section 7.4.
- Business Transfers as described in Section 7.5.
11. EffortlessGeo — Google Play Prominent Disclosure
Note for dev team: This section’s content must also be displayed as an in-app disclosure screen before requesting background location permission, as required by Google Play policy.
EffortlessGeo collects your device's location data in the background to enable your employer to track attendance, verify field visits, and monitor workforce movement during active tracking periods. This data collection occurs even when the app is closed or not in use, but requires a daily check-in to remain active.
- What is collected: GPS coordinates, timestamps, movement data, and visit photographs.
- Why: To provide attendance tracking, visit verification, live tracking, and route history services to your employer.
- Who has access: Your employer's authorized Administrators and Effortless (as the service provider).
You can disable background location access at any time through your device's Settings > Apps > EffortlessGeo > Permissions > Location. Disabling background location may prevent features like live tracking and automated attendance from working correctly.
12. Children's Privacy
Our Services are designed for use by businesses and their employees. We do not knowingly collect Personal Information from anyone under the age of 18. If we become aware that data has been collected from a minor, we will take steps to delete it promptly. If you believe a minor has provided us with Personal Information, please contact us at security@goeffortless.ai.
13. Third-Party Links and Services
Our website and Services may contain links to third-party websites or integrations with third-party services. We are not responsible for the privacy practices or content of these third parties. We encourage you to review the privacy policies of any third-party services you access.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make material changes, we will notify you through the Services, via email, or by updating the “Last Updated” date at the top of this page. Continued use of the Services after such changes constitutes acceptance of the revised policy.
15. Your Rights
Subject to applicable law, you have the right to:
- Access the Personal Information we hold about you.
- Correct inaccurate or incomplete Personal Information.
- Delete your Personal Information, subject to legal retention requirements.
- Withdraw Consent for data processing where consent is the basis for processing.
- Data Portability — request a copy of your data in a commonly used, machine-readable format.
- Object to certain types of data processing.
End Users should contact their organization's Administrator for requests related to Business Data. For all other requests, contact us at security@goeffortless.ai.
We will respond to valid requests within a reasonable timeframe and in accordance with applicable law.
16. Governing Law
This Privacy Policy is governed by and construed in accordance with the laws of India. Any disputes arising under this policy shall be subject to the exclusive jurisdiction of the courts in Chennai, Tamil Nadu.
17. Contact Us
For any questions, concerns, or requests related to this Privacy Policy or your data, please contact:
Agrya FinLabs Private Limited
Email: security@goeffortless.ai
Address: Maan Sarovar Tower, First Floor, 375/271A, Scheme Road, Teynampet, Chennai, Tamil Nadu - 600018, India